
mysslstrip
Proof-of-concept tool demonstrating MITM attack to strip SSL/TLS from MySQL connections, exploiting CVE-2015-3152 for network penetration testing.

Proof-of-concept tool demonstrating MITM attack to strip SSL/TLS from MySQL connections, exploiting CVE-2015-3152 for network penetration testing.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Pack shellcode and PE executables into evasive payloads with anti-debug, unhooking, syscall, and memory fluctuation techniques for red-team…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

High-performance Rust HTTP/HTTPS proxy with active defense: rate limiting, reputation-based access, WAF (anti-bot, anti-injection, path protection),…

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Local AI powered red teamer on a phone

A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".

SSH man-in-the-middle tool

Tests your WAF with +160 payloads

A program for testing WAF functionality